The digital transformation of operational technology (OT) systems is revolutionising industries, enhancing operational efficiency and security, and driving innovation for industrial organisations around the world. However, this transformation and closer integration with IT systems has introduced risks. Digital transformation in OT, coupled with the growing reliance on cloud technologies, presents cybersecurity challenges.
While these advancements streamline operations and improve decision-making in some respects, they expose organisations to various vulnerabilities. To harness the full potential of these different technologies, businesses must;
- adopt proactive strategies that address both opportunities and risks,
- maintain OT specialisation where required, and
- ensure that all integrations preserve all insights and value from each IT and OT system.
The promise and perils of digital transformation in OT
At its core, digital transformation in OT involves connecting and integrating traditionally siloed environments – IT systems, which typically hold and manage organisations’ data, and OT systems that control physical operations, such as manufacturing equipment or energy plants. Organisations achieve enhanced operational efficiency and greater data-sharing, as systems work together seamlessly to optimise performance.
For example, real-time data collected from OT systems can be analysed by IT platforms to predict maintenance needs, reducing downtime and costs. Similarly, this enables advanced analytics, helping organisations make data-driven decisions that improve security, safety, productivity, and innovation.
Yet, because IT and OT systems have different priorities – transformation can bring significant challenges. IT systems emphasise data confidentiality and integrity, while OT systems focus on availability and safety. This means IT security tools are ill-equipped to address cybersecurity in OT environments. For example, OT systems can’t routinely be turned off to patch vulnerabilities, and other mitigations are often required. Moreover, IT and OT teams often operate independently, with little collaboration or shared expertise. This lack of alignment can leave organisations vulnerable to cyber threats that exploit gaps in their security strategies.
A cyberattack on an OT system can enter through the IT side, then bypass IT defences to move laterally into the OT environment and disrupt critical operations such as energy distribution or transportation. Such disruptions may halt production, interrupt critical services like electricity and water supply, or jeopardise safety systems in a petrochemical facility. These challenges underscore the need for OT-specific solutions and a collaborative and comprehensive approach across all cybersecurity domains.
Trends in threat actors
The cybersecurity landscape is evolving. Threat actors are increasingly adopting new and evolving tactics to breach OT defences. But attacks are not limited to highly technical exploits. Instead, threat groups often exploit known weaknesses such as unpatched systems, poor remote access configurations, and exposed OT assets. State-sponsored actors, criminal ransomware groups, and politically motivated hacktivists now actively target critical infrastructure, aiming to disrupt essential services and operations. The lack of visibility into OT environments remains a persistent blind spot for many organisations, making them vulnerable to even basic intrusion techniques.
Global tensions have further fuelled the rise in OT-centric cyber operations. State-aligned adversaries have launched targeted campaigns against critical infrastructure in regions such as Ukraine/Russia, the Middle East, and Asia-Pacific, often as extensions of geopolitical conflicts. These operations are not only strategic but also symbolic, aiming to undermine public trust and national stability.
Meanwhile, hacktivist groups have escalated their activities, using new attack vectors to disrupt energy and water utilities. In 2023 and early 2024, there was a marked increase in hacktivist campaigns reaching Stage 2 of the ICS Cyber Kill Chain, indicating a deeper level of sophistication and intent to cause operational disruption.
A particularly concerning trend is the convergence of state-sponsored threat actors and hacktivist groups. This hybrid threat model allows nation-states to amplify their objectives through proxy actors, reducing the risk of attribution while increasing the scale and frequency of attacks.
Hacktivists are now not only aligning with geopolitical causes but also adopting ransomware tactics traditionally used by criminal groups. These developments underscore the urgent need for organisations to adopt comprehensive cybersecurity strategies that address the full spectrum of threats – from low-level exploits to coordinated, state-backed attacks.
The need for OT specialisation remains essential
While digital transformation offers immense opportunities for efficiency and innovation, it also introduces a level of connectivity for OT systems that requires a comprehensive approach. OT environments require OT-specific cybersecurity solutions due to their distinct purposes and technologies.
To achieve success for the long term, organisations must foster collaboration between IT and OT teams and follow OT-specific security best practices, such as the SANS ICS Five Critical Controls for OT Cybersecurity, to protect their applications and assets. Moreover, they must remain vigilant about the continual changes across the space, being ever prepared for new and evolving threats that emerge. By addressing these challenges head-on, organisations can unlock the huge potential of digital transformation of OT systems, driving progress while safeguarding their operations.
Dragos has a global mission to safeguard civilization from those trying to disrupt the industrial infrastructure we depend on every day. The Dragos Platform offers the most effective industrial cybersecurity technology, giving customers visibility into their ICS/OT assets, vulnerabilities, threats, and response actions. The strength behind the Dragos Platform comes from its ability to codify Dragos’s industry-leading OT threat intelligence, and insights from the Dragos services team, into the software. Dragos protects organizations across a range of industries, including electric, oil & gas, manufacturing, building automation systems, chemical, government, water, food & beverage, mining, transportation, and pharmaceutical.

















